Skip to content
Privacy & security

Local-first isn’t a setting.It\u2019s the architecture.

An assistant that learns your voice only works if you can trust where that learning lives. Cue’s answer: on your Mac, in a database you can see, behind switches you control. Here is the whole picture.

Where your data lives

Three places.Nothing hidden.

01

On your Mac, and only there

  • Your drafts history, relationship cards, promises, and memory facts
  • Voice samples: the sent messages Cue learns your tone from
  • Your personal dictionary and settings
  • Each account gets its own local database; switching users switches databases
  • One item in your macOS Keychain: Cue's own sign-in token. macOS does not let Cue read anything else stored there
02

Sent over TLS, processed, discarded

  • The text needed for the request you triggered (the thread you're replying to, your dictated audio)
  • Runs against the model through our proxy: API keys live on the server, never in the app
  • Not stored on our servers, not used to train models
  • Screenshots are sent with screen questions by default; you can turn them off in Settings
03

On our servers

  • Your account (email, via Clerk) and subscription state (via Stripe)
  • Anonymous usage counters for rate limits and fair use: numbers, not content
  • That's the list.
You hold the brakes

Every learning behaviorhas a switch.

Switch 01

Learn from what I send

The master switch for everything Cue learns from your sent messages. Off means sent text is never stored or analysed, and you can exclude specific apps (a personal messenger, a password manager) while leaving it on elsewhere.

Switch 02

Review before it remembers

Facts and promises Cue notices show up in a review list. You accept or dismiss. The only automatic case is a promise quoting your own words near-verbatim, and it arrives with an Undo.

Switch 03

Preview before insert

Drafts show up in a review card before anything touches your field. And Cue never sends a message. There is no auto-send code path at all.

Switch 04

Screenshots, on by default

So answers use what's actually on screen, Cue sends a screenshot with screen questions by default. Turn it off in Settings and Cue works from accessible text only. Screenshots are never kept after the reply.

Security posture: the app talks only to our backend over TLS; model-provider keys are held server-side and never ship in the app. Sign-in is handled by Clerk, payments by Stripe. We never see your password or card number. Accessibility access is used to read the field you invoke Cue in and to type the reply back; what it reads is used for that request and not stored.

The data path

One request,end to end.

What actually happens when you hold the key, in order, with nothing left out.

01

You trigger

Nothing leaves your Mac until you tap, double-tap, or hold the key. Idle means silent.

02

It travels over TLS

Only the moment's text or audio goes, encrypted, through our proxy, and in a live conversation, your voice streams to our cloud voice provider only while the conversation you started is open. Keys stay server-side.

03

The model runs

The reply streams straight back into the field your cursor is already in.

04

Nothing is written down

The request is processed and discarded. No server-side history of it exists.

Nothing stored

You can’t leak whatdoesn’t exist.

There is no history of your drafts, screens, or messages to leak, because we never keep one. Not encrypted, not anonymized, not retained for a while. Nonexistent.

Read the deep dive
No stored drafts: every request is processed, streamed back, and discarded
No screen history: screenshots are sent with screen questions and never kept after the reply
No message archive on our side: what Cue learns lives in a local database you can open

Private enough toactually learn you.

Free on macOS 14 and later, with a 14-day Pro trial. Questions about data? Ask us anything.